Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-29927-NextJS — PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3 | Kitploit
Tools/GitHubGitHub/liamromanis101/cve-2025-29927-nextjs
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubliamromanis101/cve-2025-29927-nextjs

CVE-2025-29927-NextJS

PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3

View Repository
1110 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

📦 Next.js CVE-2025-29927 - Proof of Concept

This repository contains a minimal Proof of Concept (PoC) for exploiting CVE-2025-29927, a high-severity vulnerability affecting specific versions of Next.js that allows unauthorized access to internal application files through crafted URLs.

⚠️ Disclaimer

This code is intended for educational and authorized security research only. Do not use it on systems you do not own or have explicit permission to test.


🚀 Getting Started

🔧 Prerequisites

  • Docker
  • Git
  • Python3.8+
    • requests, urllib.parse, re, sys

📥 Clone the Repository

git clone https://github.com/liamromanis101/CVE-2025-29927-NextJS
cd CVE-2025-29927-NextJS
python3 cbe-2025-29927.py <url>

🖼️ Screenshot

Exploit Screenshot

Download Tool